I have a client who has a Cisco ASA 5505, licensed for 10 users. It replaced a Cisco PIX 501, licensed for 50 users. The downsize from 50 users to 10 users was a mistake on the part of the purchasing agent.
I think they should have the 50 user license, as they have about 15 machines. However, in terms of concurrency, it's likely that they'll only have 5-6 machines traversing the ASA at any given time and so I'm wondering about how the ASA handles licensing.
My understanding is that the ASA considers each IP address which traverses it to be a user. Does this have a sliding expiration of some type? If user #11 hits the ASA, what does the ASA do? Does it stop working altogether? Does it deny access to user #11 only?
I want them to be properly licensed, but I'd like to understand the license rules more thoroughly in order to determine the best course of action to them.
Start Free Trial